aboutcode-org / aboutcode-org/vulnerablecode

NVD importer migration followups

Open
#679 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
702
Forks
328
Avg merge
3d 8h
Merged PRs (30d)
3

Description

@pombredanne I am starting this issue to track your comments in #664

- [ ] _Originally posted by @pombredanne in https://github.com/nexB/vulnerablecode/pull/664#discussion_r845768104_

> Why do you remove the CVEs from references?
> We still want them there IMHO ... in particular that's where we would get the severity score from the NVD?
>

- [ ] _Originally posted by @pombredanne in https://github.com/nexB/vulnerablecode/pull/664#discussion_r845771397_

> You are returning a set not a list. Should your return a sorted list then? Why using a set?

- [ ] _Originally posted by @pombredanne in https://github.com/nexB/vulnerablecode/pull/664#discussion_r845772878_

> It could make sense to:
> 1. extract the function to check if a single CVE is related to hardware
> 2. have a set of tests for this that would be easier to read including explicit tests with CPE 2.2 and 2.3 that are hardware or not.
>
> How many types of CPEs is there beyond hardware?

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.